该文在分析了 Snort 的规则及其检测过程的基础之上,提出一种动态规则匹配机制,增加选项索引链表,对规则匹配的次序进行动态调整,从而提高规则匹配的速度。 关键词:Snort 规则匹配 规则树 规则选项 Abstract: Based on the analysis of Snort’s rule and detecting procession, this paper puts forward a dynamic rule-matching mechanism. In order to adjust the sequence of rule-matching dynamically, it adds a chain of the option index. As a result, it increased the rule- matching speed effectively. Key Words: Snort Rule-matching RuleTree RuleOption